Echo: xdg-utils: security update to 1.2.1-2+e1

low Tenable Self-Hosted Container Security Plugin ID 463308

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can
facilitate CSRF. (For example, xdg-open could be modified to, by default, associate x-scheme-handler/https
with the execution of a browser with command-line options that arrange for an empty cookie store, although
this would add substantial complexity, and would not be considered a desirable or expected behavior by all
users.) NOTE: this is disputed because integrations of xdg-open typically do not provide information about
whether the xdg-open command and arguments were manually entered by a user, or whether they were the
result of a navigation from content in an untrusted origin. (CVE-2025-52968)

Solution

Update the xdg-utils library and its related packages to version 1.2.1-2+e1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-52968

Plugin Details

Severity: Low

ID: 463308

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Low

Base Score: 1.2

Temporal Score: 0.9

Vector: CVSS2#AV:L/AC:H/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2025-52968

CVSS v3

Risk Factor: Low

Base Score: 2.7

Temporal Score: 2.4

Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/9/2026

Vulnerability Publication Date: 6/23/2025

Reference Information

CVE: CVE-2025-52968